CVE-2014-3691

critical

Description

Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.

References

https://groups.google.com/forum/#%21topic/foreman-announce/jXC5ixybjqo

https://github.com/theforeman/smart-proxy/pull/217

http://rhn.redhat.com/errata/RHSA-2015-0288.html

http://rhn.redhat.com/errata/RHSA-2015-0287.html

http://projects.theforeman.org/issues/7822

Details

Source: Mitre, NVD

Published: 2015-03-09

Updated: 2023-02-13

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical